Cross-site scripting in HTML Sanitizer - CVE-2026-47345
Published: June 9, 2026
HTML Sanitizer
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in HTML serialization of namespace attributes when processing sanitized HTML content. A remote attacker can supply specially crafted input to execute arbitrary script in a victim's browser.
The issue allows bypassing the cross-site scripting prevention mechanism.